CVE-2016-3168
—CVSS 3.0
6.4 medium
EPSS
2%p84
Published
()
Modified
Description
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."
In the news0 stories
No ingested article mentions this CVE yet.